MediumVulnerability
CVE-2026-94378: The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-94378
- Published
- Record updated
Summary
CVE-2026-94378 affects the SupportCandy AI Customer Support Ticket System and Live Chatbot Agent plugin for WordPress in all versions up to and including 3.5.3. The 'name' parameter lacks sufficient input sanitization and output escaping, enabling Stored Cross-Site Scripting. An authenticated attacker with subscriber-level access or above can inject web scripts that execute whenever a user views an injected page. The exploit chain requires the 'Register user if not exists' setting to be disabled, which is its default configuration.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database